Scammers are impersonating crypto compliance services to trick users into approving transactions that drain wallets.
Regulation & Gov ·
Cybersecurity researchers at Malwarebytes identified fake AML checkers designed to deceive crypto holders into connecting wallets and authorizing transactions that could compromise their assets. The fraudulent sites imitate legitimate compliance platforms, including AMLBot, and deploy simulated scan processes with fabricated results to build credibility. Some schemes request small payments under the guise of verification fees before displaying a "Clean, Low Risk" verdict regardless of whether an actual check took place.
Legitimate anti-money laundering services require only a wallet's public address to screen for illicit activity and suspicious transaction patterns. No wallet connection or transaction approval is necessary for such a check. However, the fake variants manipulate users into linking their wallets, which exposes the full address and holdings and allows attackers to craft a transaction awaiting user approval—the critical step that enables fund theft.
Researchers found the same scam structure deployed across multiple branded sites, indicating a reused template being recycled and rebranded. Users who approved token permissions are advised to revoke access immediately. Those who entered recovery phrases or private keys should treat their wallets as compromised and transfer holdings elsewhere. Crypto transactions cannot be reversed after confirmation, making rapid response essential for anyone who has authorized a suspicious action.